Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
node-spotify-api
Advanced tools
A simple to use API library for the Spotify REST API.
npm install --save node-spotify-api
Currently there are two methods available, search
and request
🔍
search
is the EASIEST way to find an artist, album, or track.
search: function({ type: 'artist OR album OR track', query: 'My search query', limit: 20 }, callback);
var Spotify = require('node-spotify-api');
var spotify = new Spotify({
id: <your spotify client id>,
secret: <your spotify client secret>
});
spotify.search({ type: 'track', query: 'All the Small Things' }, function(err, data) {
if (err) {
return console.log('Error occurred: ' + err);
}
console.log(data);
});
Note: The limit
property is optional and the search will default to 20 if one is not supplied.
This package also optionally works with promises. Just omit the callback parameter and the search method returns a promise object containing the response:
var Spotify = require('node-spotify-api');
var spotify = new Spotify({
id: <your spotify client id>,
secret: <your spotify client secret>
});
spotify
.search({ type: 'track', query: 'All the Small Things' })
.then(function(response) {
console.log(response);
})
.catch(function(err) {
console.log(err);
});
request
can be used to make API requests to any Spotify endpoint you supply.
var Spotify = require('node-spotify-api');
var spotify = new Spotify({
id: <your spotify client id>,
secret: <your spotify client secret>
});
spotify
.request('https://api.spotify.com/v1/tracks/7yCPwWs66K8Ba5lFuU2bcx')
.then(function(data) {
console.log(data);
})
.catch(function(err) {
console.error('Error occurred: ' + err);
});
The Spotify API requires an authentication token to work. This package will perform all of the work of generating an authentication token for you, but you will still need to supply a client id and client secret.
Sign up for a Spotify developer account here. If you already have a Spotify account, you'll just have to log in. A membership can be paid or free, it makes no difference when it comes to using the Spotify API.
Once you're signed up, navigate to https://developer.spotify.com/my-applications/. You should be presented with the following page:
Click the button to "Create An App". Once you're at the next page, fill in the required fields.
Submit the form and on the next page, you should be presented with a client id and secret.
And you're all set!! 🎉
FAQs
A simple wrapper for the spotify api
The npm package node-spotify-api receives a total of 351 weekly downloads. As such, node-spotify-api popularity was classified as not popular.
We found that node-spotify-api demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.